Bug 1193372 (CVE-2021-28237) - VUL-0: CVE-2021-28237: libredwg: heap-buffer overflow via decode_preR13.
Summary: VUL-0: CVE-2021-28237: libredwg: heap-buffer overflow via decode_preR13.
Status: RESOLVED FIXED
Alias: CVE-2021-28237
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.3
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/316190/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-12-03 13:57 UTC by Thomas Leroy
Modified: 2024-06-13 17:02 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Jan Engelhardt 2022-05-16 20:43:00 UTC
977606 977605
Comment 2 OBSbugzilla Bot 2022-05-16 22:40:19 UTC
This is an autogenerated message for OBS integration:
This bug (1193372) was mentioned in
https://build.opensuse.org/request/show/977604 Factory / libredwg
https://build.opensuse.org/request/show/977605 Backports:SLE-15-SP3 / libredwg
https://build.opensuse.org/request/show/977606 Backports:SLE-15-SP4 / libredwg
Comment 3 Swamp Workflow Management 2022-05-27 10:19:23 UTC
openSUSE-SU-2022:0149-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1193372,1194767
CVE References: CVE-2021-28237,CVE-2022-21658
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    rust1.56-1.56.1-150300.7.6.1
openSUSE Backports SLE-15-SP3 (src):    libredwg-0.12.5-bp153.2.3.1
Comment 4 Swamp Workflow Management 2022-06-15 19:15:24 UTC
openSUSE-SU-2022:0155-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1193372
CVE References: CVE-2021-28237
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP4 (src):    libredwg-0.12.5-bp154.2.3.1